* Unauthenticated RCE vs all GNU/Linux systems (plus others) disclosed 3 weeks ago.
* Full disclosure happening in less than 2 weeks (as agreed with devs).
* Still no CVE assigned (there should be at least 3, possibly 4, ideally 6).
* Still no working fix.
* Canonical, RedHat and others have confirmed the severity, a 9.9, check screenshot.
* Devs are still arguing about whether or not some of the issues have a security impact.
I've spent the last 3 weeks of my sabbatical working full time on this research, reporting, coordination and so on with the sole purpose of helping and pretty much only got patronized because the devs just can't accept that their code is crap - responsible disclosure: no more.
⚠️Hier, un petit malin a enregistré https://t.co/Ehs1qNIcTv. Son titulaire peut donc créer des sites et envoyer des mails très ressemblants aux vrais .gouv.fr.
Suivant la typo, la comparaison est bluffante (ici, Lucida sans Unicode).
Vigilance sur tous les domaines .gouv.fr !
We are happy to announce that UTM SE is available (for free) on iOS and visionOS App Store (and coming soon to AltStore PAL)!
Shoutouts to AltStore team for their help and to Apple for reconsidering their policy.
https://t.co/HAV5JnT5GO
On the .xz backdoor.
It is hard to see how the developer Jia Tan is innocent. The backdoor was added in 5.6.0 by his account. He contacted Fedora to push them to move to 5.6.0. There was a problem with valgrind, they worked with hi to resolve it. He commits the fix in 5.6.1.
Introduction by @linode to Linux red teaming basic techniques
Exploitation: https://t.co/kKRI3SHW9F
Escalation: https://t.co/WRAmKTsx4t
Persistence: https://t.co/pEtfWHrSnE
#Linux#cybersecurity
Vous sentez la déprime vous gagner en ce #BlueMonday ? Lisez notre article «CentipedeRTK ou la naissance d’un géocommun», ou comment deux geeks libristes et passionnés ont révolutionné la géolocalisation centimétrique, dorénavant libre et économique : https://t.co/5Pjd74uk5r
Intro to Linux red teaming basic techniques by @linode
Exploitation: https://t.co/kKRI3SHW9F
Escalation: https://t.co/WRAmKTsx4t
Persistence: https://t.co/pEtfWHrSnE
#redteam#Linux#cybersecurity